Public distribution is one of the least glamorous and most consequential systems a state runs. If it fails, people do not receive food. That framing shaped the assessment: availability and integrity mattered as much as confidentiality, which is not the usual weighting.
Integrity over confidentiality
On most platforms we assess, the worst outcome is data leaving. Here, the worst outcome is data changing: an entitlement altered, an allocation misdirected, a record of collection created that did not happen. We tested for write paths and state transitions with the same rigour usually reserved for read access.
Penetration testing, not just scanning
The engagement was scoped as penetration testing rather than a vulnerability assessment, which means the work was manual and the objective was demonstrated impact rather than a list of potential issues. Findings were carried to proof, with reproduction steps, and rated on what an attacker could actually achieve rather than on a generic score.
Infrastructure
Departmental estates accumulate. Systems built for one programme stay online after it ends, and the forgotten ones are rarely patched. Part of the value of an external test on a government estate is simply establishing what is actually exposed, which is regularly more than the asset register says.
What was handed over
Penetration test report with proof of exploitation and impact, the CERT-In format audit deliverable, remediation guidance sequenced by risk, and retesting.













